ActionRank

mcpsnoop

Actively maintained

kerlenton/mcpsnoop · MIT

Wireshark for MCP. A transparent proxy between your AI client and MCP server. Watch every call live in your terminal, fail CI on what it finds, export OpenTelemetry spans.

★ 361 starsLast commit 3 days agoLatest v0.26.1
B
77
/ 100
Security 75Maintenance 100Popularity 51Reliability 70

Security signals

OpenSSF ScorecardNo data
SECURITY.md presentYes
Immutable releasesNot enabled
Known vulnerabilitiesNone on record

How to use it safely

Recommended: pin to commit SHA
uses: kerlenton/mcpsnoop@e027c0a125d2c8b28ce9d5be4a4dc2f33f56774a # v0.26.1

Mutable tags like v0.26.1 can be rewritten to point at malicious commits. Pinning to the full commit SHA is the only reference GitHub guarantees immutable.

Full workflow example
steps:
  - uses: kerlenton/mcpsnoop@e027c0a125d2c8b28ce9d5be4a4dc2f33f56774a # v0.26.1

Score breakdown

Security (35%)75
Popularity (20%)51
Maintenance (30%)100
Reliability (15%)70

Add this badge to your README

ActionRank grade badge for mcpsnoop
Markdown
[![ActionRank](https://actionrank.dev/api/badge/kerlenton-mcpsnoop)](https://actionrank.dev/actions/kerlenton-mcpsnoop)
HTML version
HTML
<a href="https://actionrank.dev/actions/kerlenton-mcpsnoop"><img src="https://actionrank.dev/api/badge/kerlenton-mcpsnoop" alt="ActionRank score"></a>

Free to use, no attribution required — the badge updates itself as the score changes. How badges work

Get alerts for mcpsnoop

We'll email you only if mcpsnoop becomes abandoned or a new advisory is published. Unsubscribe any time. How we handle your address